Splunk Search

lookup - append only columns with values

fedejko
Explorer

Hi,

I've got a lookup with a number of records, and not all of them have all columns populated. Is there a way to append only those columns which are not empty?

Something similar to:

 

| lookup mylookup lookup_key OUTPUTNEW list of columns to append
| <some SPL here to hide columns which are empty>

 

I'd be grateful for any tips.  I was experimenting with foreach but with no results.

Regards

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...

New Dates, New City: Save the Date for .conf25!

Wake up, babe! New .conf25 dates AND location just dropped!! That's right, this year, .conf25 is taking place ...

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...